Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
I am this person. I work as a researcher finding 0-days. From the employee perspective: Wages are equal. Big Tech work is less interesting (build big bug finding machines that find have high quantity of bugs) and report the bugs that sit into some bug tracker only to maybe be fixed in 3 months. Offensive security work is more interesting. It requires intimate knowledge of the systems you research, since you only need…
0-days exploited by commercial surveillance vendor in Egypt
201–210 of 254 posts
Re: 0-days exploited by commercial surveillance vendor in Egypt
#202Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
These exploits are weapons. Look at what governments pay for weapons. That's hard to compete with.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#203Earlier quoted context omitted.
If you're saying "EAL4 and below is junk" (I'd say EAL* is junk, but whatever), all you're really saying is that minimal-function cryptographic coprocessors are safer than operating systems and applications. Well, yeah, sure. I don't think you needed the farce of Common Criteria to tell you that, though. But upthread, you knocked Apple for not achieving an adequate assurance level. As you can see now, and from your o…
No. The Separation Kernel Protection Profile (SKPP) defines a model for a operating system kernel at EAL6+. So all I am really saying is that safe operating systems are safer than non-safe operating systems. You could also look backwards to the TCSEC and the comparable certified Level A1 systems for other operating systems designed for actual high security work. You keep calling it a farce, but you keep pointing at E…
Re: 0-days exploited by commercial surveillance vendor in Egypt
#204Earlier quoted context omitted.
Can confirm as someone who has to renew a non-Let’s Encrypt cert every year (for reasons). The CA sends an automated email to the email address listed in WHOIS, you click a link in the email, and they issue the certificate. No human interaction necessary.
EV certs have a slightly more rigorous approach. They’ll call the registered agent for the business as registered/licensed with the state, not the phone number from whois or an email to webmaster@
Re: 0-days exploited by commercial surveillance vendor in Egypt
#205Earlier quoted context omitted.
I think this is similar to looking at the budget of the US government and asking why they don't simply pay off all the potential criminals such that most crime in the US is then mitigated.
That’s not equivalent at all. Paying off criminals creates an incentive for there to be more criminals. Paying more security researchers does not incentivize people writing buggy C code to write even buggier C code.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#206Earlier quoted context omitted.
If you're a nation you can just force the CAs that are in your jurisdiction to do whatever you want, or sneak in in various ways so they won't know. If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.
CT means a CA can’t do whatever they want. Your comment is handwavy, do you have any details on the “various ways” you’re talking about?
Re: 0-days exploited by commercial surveillance vendor in Egypt
#207Earlier quoted context omitted.
CT means a CA can’t do whatever they want. Your comment is handwavy, do you have any details on the “various ways” you’re talking about?
I think it’s true that they can do “whatever they want”, but only once, because they’ll lose the right once found. The issue is the time between breach and punishment.
Of course then the question is how quickly browsers can roll out an update/config to distrust all future certs from said CA.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#208Earlier quoted context omitted.
Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.
> Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”. There is certainly many of those that we don't know about, if this was done in Egypt, imagine what a 3 letters agency have
The going price was $1m for a full exploit chain on iPhone a while ago, and I’m sure it’s gone up, but I’m also sure it is minuscule compared to the amount of money governments have.
Everyone should assume this is fact, and not imagine some secret spy world. If you ever become interesting enough to hack, you will be, and there is little recourse (currently)
Re: 0-days exploited by commercial surveillance vendor in Egypt
#209Earlier quoted context omitted.
> Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”. There is certainly many of those that we don't know about, if this was done in Egypt, imagine what a 3 letters agency have
Every government with money has exploits for every device imaginable. The going price was $1m for a full exploit chain on iPhone a while ago, and I’m sure it’s gone up, but I’m also sure it is minuscule compared to the amount of money governments have. Everyone should assume this is fact, and not imagine some secret spy world. If you ever become interesting enough to hack, you will be, and there is little recourse (c…
Re: 0-days exploited by commercial surveillance vendor in Egypt
#210Earlier quoted context omitted.
There are millions of android devices out there that have been abandoned by their manufacturers, so they might be omitting those details because the flaw hasn't yet been patched (and likely never will be.)
Even with Google's own flagship device, the latest security patches date from August while this announcement is much newer, so it seems unlikely _any_ Android devices have been patched.